The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This is similar to CVE-2021-22881. Strings in config.hosts that do not have a leading dot are converted to regular expressions without proper escaping. This causes, for example, config.hosts << "sub.example.com" to permit a request with a Host header value of sub-example.com.
{
"binaries": [
{
"binary_name": "rails",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-actioncable",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-actionmailbox",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-actionmailer",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-actionpack",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-actiontext",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-actionview",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-activejob",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-activemodel",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-activerecord",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-activestorage",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-activesupport",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-rails",
"binary_version": "2:6.1.7.3+dfsg-3"
},
{
"binary_name": "ruby-railties",
"binary_version": "2:6.1.7.3+dfsg-3"
}
]
}{
"binaries": [
{
"binary_name": "rails",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-actioncable",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-actionmailbox",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-actionmailer",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-actionpack",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-actiontext",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-actionview",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-activejob",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-activemodel",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-activerecord",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-activestorage",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-activesupport",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-rails",
"binary_version": "2:7.2.2.1+dfsg-7"
},
{
"binary_name": "ruby-railties",
"binary_version": "2:7.2.2.1+dfsg-7"
}
]
}{
"binaries": [
{
"binary_name": "rails",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
},
{
"binary_name": "ruby-actionmailer",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
},
{
"binary_name": "ruby-actionpack",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
},
{
"binary_name": "ruby-actionview",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
},
{
"binary_name": "ruby-activejob",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
},
{
"binary_name": "ruby-activemodel",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
},
{
"binary_name": "ruby-activerecord",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
},
{
"binary_name": "ruby-activesupport",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
},
{
"binary_name": "ruby-rails",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
},
{
"binary_name": "ruby-railties",
"binary_version": "2:4.2.6-1ubuntu0.1~esm2"
}
]
}{
"binaries": [
{
"binary_name": "rails",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
},
{
"binary_name": "ruby-actionmailer",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
},
{
"binary_name": "ruby-actionpack",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
},
{
"binary_name": "ruby-actionview",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
},
{
"binary_name": "ruby-activejob",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
},
{
"binary_name": "ruby-activemodel",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
},
{
"binary_name": "ruby-activerecord",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
},
{
"binary_name": "ruby-activesupport",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
},
{
"binary_name": "ruby-rails",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
},
{
"binary_name": "ruby-railties",
"binary_version": "2:4.2.10-0ubuntu4+esm2"
}
]
}{
"binaries": [
{
"binary_name": "rails",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-actioncable",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-actionmailer",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-actionpack",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-actionview",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-activejob",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-activemodel",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-activerecord",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-activestorage",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-activesupport",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-rails",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
},
{
"binary_name": "ruby-railties",
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1"
}
]
}{
"binaries": [
{
"binary_name": "rails",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-actioncable",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-actionmailbox",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-actionmailer",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-actionpack",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-actiontext",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-actionview",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-activejob",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-activemodel",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-activerecord",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-activestorage",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-activesupport",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-rails",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
},
{
"binary_name": "ruby-railties",
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1"
}
]
}